Tag: system privilege预览模式: 普通 | 列表

How to create process as system privilege?

How to create process as system privilege?
here is a way to do this in kernel mode driver: (for WinXP/2003)
Hook undocumented API: ZwCreateProcessEx
then set the fouth parameter to SYSTEM handle info.

查看更多...

Tags: system privilege

分类:Tech | 固定链接 | 评论: 0 | 引用: 0 | 查看次数: 6735

how to change process privilege to system

how to change process privilege to system?

process token privilege is store in EProcess structure:
Win2000: EProcess+$12C
WinXP SP2: EProcess+$C8
Win2003 SP2 EProcess+$D8

查看更多...

Tags: system privilege

分类:Tech | 固定链接 | 评论: 1 | 引用: 0 | 查看次数: 3534